CVE-2023-24999: Vault Fails to Verify if the AppRole SecretID Belongs to Role During a Destroy Operation
A flaw was found in the Hashicorp vault. When using the Vault and Vault Enterprise approle auth method, any authenticated user with access to the /auth/approle/role/:rolename/secret-id-accessor/destroy endpoint can destroy the secret ID of another role by providing the secret ID accessor.
Other sources
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor. This vulnerability is fixed in Vault 1.13.0, 1.12.4, 1.11.8, 1.10.11 and above.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24999?
CVE-2023-24999 is a vulnerability found in Hashicorp Vault that allows authenticated users to destroy the secret ID of any role.
What is the severity of CVE-2023-24999?
CVE-2023-24999 has a severity rating of 8.1, which is considered high.
How does CVE-2023-24999 affect Hashicorp Vault?
CVE-2023-24999 affects Hashicorp Vault and Vault Enterprise's approle auth method.
How can I fix CVE-2023-24999?
To fix CVE-2023-24999, update your version of Vault to 1.13.0, 1.12.4, 1.11.8, 1.10.11 or above.
Where can I find more information about CVE-2023-24999?
You can find more information about CVE-2023-24999 at the following references: [Hashicorp Discuss](https://discuss.hashicorp.com/t/hcsec-2023-07-vault-fails-to-verify-if-approle-secretid-belongs-to-role-during-a-destroy-operation/51305), [Red Hat Errata](https://access.redhat.com/errata/RHSA-2023:3742), [Red Hat Security Advisory](https://access.redhat.com/security/cve/cve-2023-24999).